Все публикации

CMSTP.exe - remote sct execution

xwizard.exe - remote .sct execution

Powersct

OneDrive - DLL hijack

MSBuild - PSAttack

msiexec.exe - arbitrary DLL execution

CompatTelRunner.exe DLL Hijack

.cpl - Whitelist Bypass

COM Hijacking - Whitelist Bypass

corgen.exe vs locked-down workstation

coregen.exe - Whitelist Bypass

C2 Server with Docker, Nginx and Metasploit

AppLocker Bypass Techniques

Phishing with ClickOnce

SMB Relay with Snarf

Exploitation with SMB Relay

Exploitation and Persistence with Metasploit, Powershell and WMI

Phishing with Powershell, HTA and Metasploit

Lab Setup